Improvement & Transformation
AmberWolf combines improvement and transformation services with practical, expert guidance to guide clients, strengthen their defences, reduce risk, and embed security into technology, processes, and culture - enabling safe growth and confident digital innovation. We employ automated and manual techniques to uncover vulnerabilities, identify innovative solutions and increase organisation-wide cybersecurity.
Features
- Strategic analysis: top-down ownership of cloud service/system transformation
- Transformation that modernises security, strengthens defences and builds lasting resilience
- Security remediation: developing solutions for system, application and process vulnerabilities
- Architecture transformation: technical assessments, roadmap development and project management
- Software development, embedding security across SDLC and CI/CD pipeline
- Transformation leadership: enabling behavioural change to align decision-making with objectives.
- AI testing: safeguarding transformed systems and teams from emerging threats
- Deep-dive risk and mitigations support from experienced cybersecurity strategy consultants
- Accredited advice from experts, combining strategic foresight and comprehensive expertise
Benefits
- Expert security transformation guidance and advice with practical implementation support
- UK Cyber Security Council–Chartered Cyber Security Professionals, NCSC-aligned
- Tailored improvement strategy implemented to drive transformation delivery efficiency
- Defined cybersecurity strategy, translated into organisation-wide objectives, outcomes and KPIs
- Organisational resilience via risk assessment, resource planning and workforce training
- Artificial Intelligence (AI) solutions leveraged to future-proof outputs and security
- Bespoke, flexible support and expertise, embedding cybersecurity without unnecessary overhead
- Hands-on tactical support, tailored to each organisation’s requirements and priorities
- Long term cybersecurity support alongside on-the-ground support for immediate issues
- Secure-by-design solutions to transformation objectives, aligned to regulatory/industry standards
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 0 9 6 2 9 1 8 5 6 2 1 4 2 8
Contact
AMBERWOLF LIMITED
Chris Weston
Telephone: 07748111883
Email: chris.weston@amberwolf.com
About your service
- Service categories
-
Cloud Support Services
Security Services
- Security strategy
- Security risk management
- Security audit services
- Security quality assurance (QA) and testing
Service scope
- Service constraints
-
Client System Availability: Certain services and tests require systems to be available for assessment, with access to the environments and associated accounts and credentials.
Client Authorisation: We require a signed authorisation form in line with computer misuse act.
Remote Consultants: all staff operate and provide support remotely.
User support
- Email or online ticketing support
- Yes
- Support response times
-
Typically:
Monday to Friday 9am to 5pm: within one working day
Out-of-hours: the next working day
Alternative response times to be discussed during mobilisation. - User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
- Support enquiries are handled by our dedicated consulting team, ensuring each request receives the right level of expertise. We will assess the complexity/requirements of your request and escalate to an appropriately experienced member of staff (In escalating order: Consultant, Team Leader, Director) to ensure your issue can be resolved quickly/effectively. This gives you direct access to experienced cybersecurity professionals, minimising risks and maintaining operational continuity. Planning, pre-requisites, prep calls, initiation, updates, comms during project, post project read out and wash-up/clean-up is part of standard service and does not incur additional costs. Remediation and continued advisory post project will cost additional.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Pricing
- Discount for educational organisations
- No
Architecture roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Enterprise architect | £1,150.00 | |
| Senior enterprise architect | £1,250.00 | |
| Lead enterprise architect | £1,350.00 | |
| Principal enterprise architect | £1,450.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate network architect | £1,250.00 | |
| Network architect | £1,350.00 | |
| Lead network architect | £1,450.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Security architect | £1,350.00 | |
| Lead security architect | £1,450.00 | |
| Principal security architect | £1,500.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate solution architect | £1,150.00 | |
| Solution architect | £1,250.00 | |
| Senior solution architect | £1,350.00 | |
| Lead solution architect | £1,450.00 | |
| Principal solution architect | £1,500.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate technical architect | £1,150.00 | |
| Technical architect | £1,250.00 | |
| Senior technical architect | £1,350.00 | |
| Lead technical architect | £1,450.00 | |
| Principal technical architect | £1,500.00 |
Chief digital and data roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Chief information security officer | £1,800.00 |
Cyber security roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Lead cyber security audit and assurance | £1,250.00 | |
| Principal cyber security audit and assurance | £1,450.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security governance and risk manager | £1,150.00 | |
| Lead cyber security governance and risk manager | £1,350.00 | |
| Principal cyber security governance and risk manager | £1,450.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security testing | £1,350.00 | |
| Lead cyber security penetration testing | £1,650.00 | |
| Principal cyber security testing | £1,850.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate cyber security secure systems architecture and design | £1,500.00 | |
| Lead cyber security secure systems architecture and design | £1,650.00 | |
| Principal cyber security secure systems architecture and design | £1,800.00 |
IT operations roles
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate application operations engineer | £1,150.00 | |
| Application operations engineer | £1,250.00 | |
| Senior application operations engineer | £1,350.00 | |
| Lead application operations engineer | £1,450.00 | |
| Principal application operations engineer | £1,500.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate end user computing engineer | £1,150.00 | |
| End user computing engineer | £1,250.00 | |
| Senior end user computing engineer | £1,350.00 | |
| Lead end user computing engineer | £1,450.00 | |
| Principal end user computing engineer | £1,500.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Incident manager | £1,500.00 | |
| Major incident manager | £2,000.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate infrastructure engineer | £1,150.00 | |
| Infrastructure engineer | £1,250.00 | |
| Senior infrastructure engineer | £1,350.00 | |
| Lead infrastructure engineer | £1,450.00 | |
| Principal infrastructure engineer | £1,500.00 |
| Role level | UK Rate | Offshore Rate |
|---|---|---|
| Associate infrastructure operations engineer | £1,150.00 | |
| Infrastructure operations engineer | £1,250.00 | |
| Senior infrastructure operations engineer | £1,350.00 | |
| Lead infrastructure operations engineer | £1,450.00 | |
| Principal infrastructure operations engineer | £1,500.00 |
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- United Register of Systems
- ISO/IEC 27001 accreditation date
- Friday 14 March 2025
- What the ISO/IEC 27001 doesn’t cover
- Full coverage
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 6068d00c-879d-4aaa-a0ff-149a8e5b926e
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9dc99fc0-4c3b-4873-b2fc-a687ec96da19
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Plans for an appropriate income replacement policy for staff who are required to spend time away from work to care for a sick dependent or close relative
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Outline policies and practices to be applied to or put in place for the contract to mitigate and manage modern slavery risks, including: Pre-employment checks, recruitment practices. Workplace conditions, safeguarding plans and processes in place and regular monitoring with relevant groups considered, which may include sampling
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of issues relating to entering the contract workforce
- Creation of outreach activities to create a pipeline of employees for the future contract delivery
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-